Illustrative image generated with AI
Pegasus Hits Serbia’s Student Movement with a Zero-Click iMessage Exploit
Citizen Lab confirmed Pegasus zero-click iMessage compromise of Serbian student activist's iPhone, amid 14 spyware targets and NoviSpy Android cases.
Text generated by artificial intelligence, published without human review. AI transparency
An iPhone Compromised Without Any Action by the Victim
Citizen Lab and SHARE Foundation have confirmed the compromise of an iPhone belonging to a member of Serbia’s student movement by Pegasus, the mercenary spyware developed by NSO Group.
The incident, which came to light on September 3, 2026, involved an attack attributed with high confidence to a zero-click exploit delivered through Apple iMessage. This technique can compromise a device without requiring the target to open an attachment, follow a link, or respond to a message.
Forensic traces identified on the phone cover the period from December 2025 to January 2026. Investigators have not ruled out the possibility that other undetected infections may have occurred.
The exact iPhone model, the version of iOS installed at the time of the attack, and the precise date of the compromise are unknown. This information would be needed to reconstruct the infection chain more accurately and determine why the device remained vulnerable.
The iMessage exploit associated with the case was reportedly fixed by Apple in iOS 18.4.1, released in April 2025. The patch therefore predates the period covered by the forensic indicators. Without the phone’s configuration, it is impossible to determine whether the target was running an earlier version of iOS or whether other factors were involved.
No CVE identifier has been assigned to the vulnerability. There is also no information indicating that it was added to CISA’s Known Exploited Vulnerabilities catalog.
Apple Notifications Reached Users in 110 Countries
The investigation followed a new round of notifications sent by Apple to people considered potential targets of mercenary spyware. The alerts reached users in 110 countries, although the total number of recipients was not disclosed.
These notifications do not automatically prove that a phone has been compromised. They do indicate, however, that Apple detected activity consistent with highly targeted surveillance campaigns, which generally differ from malware distributed on a broad scale.
In the Serbian case, subsequent forensic analysis linked the infection to Pegasus and an interaction-free iMessage delivery vector. The attribution concerns the tool used; no technical evidence has been provided that would publicly identify the platform operator or reconstruct its infrastructure.
No domains, IP addresses, hashes, or other indicators of compromise usable by administrators for independent searches have been disclosed. Verification therefore requires provider notifications, forensic acquisition, and specialist device analysis.
At Least 14 People Targeted in Serbia Since the Start of 2026
The case does not appear to be isolated. According to SHARE Foundation, at least 14 people in Serbia have been targeted with advanced spyware since the beginning of 2026.
The targets include members of the student movement, activists, a member of parliament, and a local councilor affiliated with opposition parties. The incidents coincided with the local elections held on March 29, 2026, placing the surveillance operations in a politically sensitive period.
The reported number may not reflect the full scope of the campaign. Zero-click infections can leave limited traces, while some victims may not have received alerts or had their phones subjected to forensic examination.
The consequences extend beyond individual privacy. The compromise of members of political and civic movements can expose contact networks, internal communications, and information about organizational activities. In the Serbian case, there is also concrete evidence that private material stolen from a smartphone was used publicly.
NoviSpy Installed on Seized Android Phones
Alongside the Pegasus campaign, two incidents involving a new variant of the NoviSpy Android spyware have emerged.
A member of the student movement had their phone compromised after the device was seized during a police interrogation. The circumstances differ from the zero-click attack against the iPhone: in this case, the person operating the phone is believed to have had physical access to the device.
SHARE Foundation detected the same NoviSpy variant on a second smartphone. Private Viber messages had been extracted from that device and were later broadcast live by Informer TV, a pro-government Serbian television channel.
The incident demonstrates an immediate and verifiable impact. The acquired data reportedly did not remain limited to surveillance activity but was used to make the target’s private communications public.
Amnesty International Security Lab believes that Serbian authorities installed invasive Android spyware tools while students were in detention. The new threat offers functionality similar to NoviSpy but includes changes specifically designed to hinder researchers’ work and reduce the likelihood of detection.
The affected Android versions and any vulnerabilities exploited by the new variant are unknown. It is also unclear whether installation requires the phone to be unlocked or can be performed using forensic tools capable of bypassing its protections.
The Role of Cellebrite Forensic Tools
The new compromises follow previously documented cases in Serbia in which Cellebrite forensic tools were used to deploy NoviSpy.
Mobile forensics platforms are designed to acquire data from devices as part of investigations. When combined with invasive spyware, however, they can turn a temporary seizure into persistent access to a phone, even after it has been returned.
This approach leaves students, journalists, activists, and opposition figures summoned for questioning particularly vulnerable. Users may regain possession of a device that appears intact while the installed software attempts to conceal its presence.
The anti-detection modifications identified in the new Android threat also indicate adaptation to techniques used by independent laboratories. Insufficient detail has been disclosed to determine which system components are modified or which safeguards are bypassed.
Updates and Protection Measures for At-Risk Users
The first step for Apple users is to install all available updates. In this specific case, the iMessage exploit fix is included in iOS 18.4.1. Anyone using a compatible device should verify that it has not remained on an earlier version.
People exposed to targeted surveillance may consider enabling Lockdown Mode. This configuration reduces the attack surface by restricting certain features and content that sophisticated spyware can exploit.
For Android, Google recommends that high-risk users enroll in the Advanced Protection Program, which applies stricter controls to accounts and sign-in procedures.
Meta has also introduced Strict Account Settings on WhatsApp. The setting automatically applies stronger protections and blocks attachments and media sent by contacts who are not saved in the address book.
These measures reduce risk but do not replace forensic analysis when there is a credible suspicion of compromise. Anyone who receives an Apple threat notification, has their phone temporarily seized, or notices the unusual circulation of their communications should preserve the device and contact qualified specialists, avoiding resets that could erase valuable evidence.
Sources
This article is an original reworking based on the sources below.
